External risk intelligence

WP OAuth Server Identity Assertion Forgery Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.0)

CVE-2026-82843

This plugin implements identity assertion and single sign-on (SSO) functionality, which is designed to be public-facing to facilitate authentication across different applications. By its nature as an identity provider, it acts as a gateway service that must be internet-accessible to perform its core role.

Authentication Bypass

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects a WordPress plugin that handles user logins and single sign-on. It could allow unauthorized access to user accounts, including administrator accounts, by misusing identity assertions. The primary concern is to confirm if this plugin is in use and exposed externally.

  • Misused login information allows account takeover.
  • Enables single sign-on impersonation risks.
  • Confirm plugin use and external exposure.

Attack Path

How an attacker could exploit the issue

An attacker with low privileges on a WordPress site can impersonate other users, including administrators, by exploiting a flaw in how the WP OAuth Server plugin handles identity assertions. This allows them to authenticate as any user to applications relying on the site for single sign-on.

  • Requires low-privileged user access.
  • Vulnerability triggered during token exchange.
  • Risk of full account takeover.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, this vulnerability could allow a user with the Subscriber role or higher to obtain a signed identity assertion for another user, potentially including an administrator. This assertion could then be used to authenticate as that other user to any application utilizing the site for single sign-on.

  • Administrator account access.
  • Impersonation via identity assertion.
  • Unauthorized application access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts WordPress sites utilizing the WP OAuth Server plugin for OpenID Connect single sign-on. Ownership likely resides with the website's application or platform team, supported by the vendor management team for plugin updates. The immediate first step is to identify all instances of the affected plugin, determine which are internet-facing and critical, and confirm the accountable owner for remediation.

  • Application owners should prioritize this.
  • Verify internet-facing instances and impact.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the WP OAuth Server plugin?

WP OAuth Server is a WordPress plugin that enables the site to act as an OpenID Connect identity provider. It allows external applications to offload their authentication process to the WordPress site, enabling users to log into those third-party services using their WordPress credentials via single sign-on (SSO).

What does CWE-287 mean for CVE-2026-82843?

CWE-287 refers to improper authentication. In this CVE, the plugin fails to correctly link an identity assertion to the specific authorization grant being processed. Instead of verifying the identity of the person requesting access, the system incorrectly issues the assertion of the user who most recently logged in, leading to potential identity confusion.

How is this identity flaw triggered?

An attacker must have at least a Subscriber-level account on the WordPress site to initiate the attack. The flaw is triggered during the token exchange process. It is not triggered by casual site visitors who lack a registered account, as the exploit requires the ability to interact with the plugin's authenticated request flows.

Is my site at risk according to Halo Surface Signal?

According to Halo Surface Signal, this plugin is highly likely to be internet-facing because it serves as an identity provider for external applications. If your WordPress site uses this plugin to provide SSO services, it is inherently positioned to be accessible from the network, making it a relevant point of concern for account integrity.

When should I take action for this vulnerability?

You should prioritize reviewing your environment immediately to confirm if this plugin is installed. Identify all instances where it is active and internet-accessible. Once identified, coordinate with your application owners to plan for the update to version 6.4.0 or later to resolve the assertion binding defect.

References